Is catlean_1.21.11-v0.1.2.jar safe?
No antivirus engine detected this established JAR, and its completed sandbox run and fully covered host check produced no corroborating malware finding.
None of 75 antivirus engines flagged the file, including all 17 reporting tier-1 engines. It is broadly established, and one completed sandbox run plus the fully covered contacted-host check produced no malicious finding, although two offensive-capable techniques and six unclassified child hashes warrant ordinary caution.
395d94f86df20d91f4…e601aa6a289ab2Recommended next actions
Before opening or running
Open or run it only when its publisher and download source have been independently verified.
If you already opened or ran it
Keep normal device protection enabled and stop if the file behaves unexpectedly.
Intelligence
The saved assessment, checked against the scan evidence and recorded coverage.
The reasoning behind this verdict
This section explains the evidence supporting the verdict and keeps conflicting or missing signals visible.
None of 75 antivirus engines flagged the file, including all 17 reporting tier-1 engines. It is broadly established, and one completed sandbox run plus the fully covered contacted-host check produced no malicious finding, although two offensive-capable techniques and six unclassified child hashes warrant ordinary caution.
The strongest evidence is unanimous engine silence: 0 of 75 engines detected the JAR, including 17 reporting tier-1 engines. The file has also accumulated 1,301 submissions from 1,177 sources, reducing concern that it is an unseen or newly introduced sample. One completed sandbox run did not produce a malicious verdict, and reputation checking covered its single observed domain without a malicious or suspicious match. Static and runtime telemetry nevertheless includes T1543.002 and T1562.001, so those capabilities should be considered in context rather than ignored. Six written-file hashes were inspected without a malicious child result, but their individual classifications remain unknown. With no external-intelligence hits or fired heuristics, the overall evidence favors ordinary established software.
What We Detected
None of 75 antivirus engines flagged the JAR, and all 17 reporting tier-1 engines returned no detection. The sample is established in circulation, with 1,301 submissions from 1,177 sources, and no matching malware family was identified.
Threat Behavior
One completed sandbox run did not issue a malicious verdict. It recorded T1543.002 and T1562.001 alongside eight more common techniques, but no persistence indicators, malicious child verdict, or malicious contacted-host match was found. The host-reputation check inspected the single observed domain, while all six written-file hashes still lack individual classifications.
What To Do Now
Use the JAR only if it came from the expected project or distribution channel, and keep endpoint protection enabled. If its origin is uncertain, verify the SHA-256 hash and project release information before running it.
Where this verdict could be wrong2 caveats
- behaviour.offensiveTechniques lists T1543.002 and T1562.001, which can indicate service manipulation and impaired defenses, though the single sandbox did not issue a malicious verdict.
- droppedChildren inspected six hashes, but all six have unknown verdicts; hasMaliciousChild=false therefore does not establish that those children are benign.
These are the assessment's weak points. If you believe one applies to your file, report the verdict and we'll re-review it.
- 0/75 antivirus engines reported a detection.
- 17 tier-1 engines reported no detection.
- One completed sandbox produced no malicious verdict.
- The only observed domain was fully checked with no malicious or suspicious cache match.
- The sample has 1,301 submissions from 1,177 sources.
- Runtime telemetry includes offensive-capable techniques T1543.002 and T1562.001.
- All six inspected dropped-child hashes have unknown individual verdicts.
- JAR signing is not applicable in this evidence, so publisher identity was not authenticated.
Use it when obtained from the expected project channel and when the SHA-256 matches the published release. Keep antivirus and endpoint protection enabled during installation and use.
Coverage & freshness
Complete means the check returned a usable result. It does not mean the file is safe.
Antivirus
Complete0 of 75 engines flagged the file.
Sandbox
Complete1 isolated runtime environment contributed observations.
Network
Complete1 contacted host was cross-checked.
YARA
CompleteRule evaluation completed with no recorded matches.
External intel
Complete3 of 3 independent reference sources completed.
Behavior
Plain-English impact first, then the observed runtime evidence.
Runtime flight recorder
Capture complete- 1isolated sandbox run
- 10MITRE ATT&CK techniques
- 11spawned processes
- 1network contacts
- 13filesystem & mutex artifacts
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- edge.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com
- C:\Users\<USER>\AppData\Local\Temp\hsperfdata_<USER>\812
- C:\ProgramData\Oracle\Java\.oracle_jre_usage\3903daac9bc4a3b7.timestamp
- C:\ProgramData\Oracle\Java\.oracle_jre_usage\17dfc292991c8786.timestamp
- C:\Users\user\AppData\Local\Temp\hsperfdata_user
- C:\Users\user\AppData\Local\Temp\hsperfdata_user\7048
- C:\Users\user\AppData\Local\Temp\hsperfdata_user\6852
- /tmp/hsperfdata_root/4991
Files this sample writes at runtime
This file drops 6 children at runtime. None are currently flagged malicious in our cache.
- ea4b3c8e1c9122a7987f…d5d026Never scannednever seen before
- 0f222643fb1060cfdbb8…e3c2f9Never scannednever seen before
- 3f8096f14540c8e18e4e…ad10b8Never scannednever seen before
- d87c5f3cdfb5b7c0510e…1ade9eNever scannednever seen before
- 44a3bab2c338e3bca24c…d3b9e7Never scannednever seen before
- ac941ead01d5451a7a9f…253227Never scannednever seen before
Detection & Forensics
Consensus, attribution, signatures, code structure, prevalence, and identity.
Evidence integrity
Chain of custody for the facts preserved in this report.
- 0rule hits recorded
- 0 / 75engines flagged
- 1,177sources in submission history
Why these facts are shown
Each statement identifies whether it was directly recorded or derived from saved scan facts.
- 01
0 of 75 antivirus engines flagged the file.
Verdict inputView chapterProvenanceObservedSourceAntivirus analysisObserved at - 02
The hash has a long, established submission history across 1,177 sources.
Verdict inputView chapterProvenanceDerivedSourceSubmission historyObserved at - 03
The hash has been submitted 1,301 times from 1,177 sources.
ProvenanceDerivedSourceSaved report factsObserved at - 04
Scanned file: catlean_1.21.11-v0.1.2.jar — 395d94f86df20d91f495b4f61b61a67318a326a5885fafcdefe601aa6a289ab2
ProvenanceObservedSourceUploaded fileObserved at - 05
Observed process — "C:\Program Files\Java\jre-1.8\bin\java.exe" -jar "C:\Users\<USER>\Desktop\runtime.jar"
ProvenanceObservedSourceIsolated runtime analysisObserved at - 06
Observed process — C:\Windows\system32\icacls.exe C:\ProgramData\Oracle\Java\.oracle_jre_usage /grant "everyone":(OI)(CI)M
ProvenanceObservedSourceIsolated runtime analysisObserved at - 07
File written: 812 — C:\Users\<USER>\AppData\Local\Temp\hsperfdata_<USER>\812
ProvenanceObservedSourceIsolated runtime analysisObserved at - 08
File written: 3903daac9bc4a3b7.timestamp — C:\ProgramData\Oracle\Java\.oracle_jre_usage\3903daac9bc4a3b7.timestamp
ProvenanceObservedSourceIsolated runtime analysisObserved at - 09
Contacted host: edge.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com — Contact observed during runtime.
ProvenanceObservedSourceIsolated runtime analysisObserved at
Detection sources at a glance
The available sources did not agree on a named threat category.
MalwareBazaar, YARAify, and CIRCL hashlookup completed and returned no entries for this hash.
YARA rules
No matchesThe rule pass completed without a saved public match.
0 of 75 engines flagged this file
View all 75 engine results
PE structure
Not applicablePE structure analysis applies to Windows executable formats, not this file type.
How widely this file has been seen
Widely seen in the wild for a long time. High prior this is legitimate; isolated detections on common-old files are usually false positives.
Fingerprint and provenance
- File name
- catlean_1.21.11-v0.1.2.jar
- Format
- JAR
- Code signing
- Not applicable to this file type
- Size
- 10.6 MB
- Last analyzed
- Oct 5, 2026, 5:07 PM UTC
395d94f86df20d91f495b4f61b61a67318a326a5885fafcdefe601aa6a289ab2Safety & FAQ
Complete recovery guidance and answers for the next decision.
What to do now
This file appears low risk based on the evidence available now.
- Recovery step 01
Open or run it only when its publisher and download source have been independently verified.
- Recovery step 02
A clean result reduces known risk, but it cannot guarantee that every new or targeted threat has been detected.
- Recovery step 03
Keep your antivirus and Windows updates switched on so you stay protected.
Safety FAQ
Direct answers grounded in the saved verdict and evidence in this report.
Is catlean_1.21.11-v0.1.2.jar safe?
What is catlean_1.21.11-v0.1.2.jar?
How many antivirus engines detected catlean_1.21.11-v0.1.2.jar?
What is the SHA-256 hash of catlean_1.21.11-v0.1.2.jar?
Is it safe to open or run catlean_1.21.11-v0.1.2.jar?
How up to date is this analysis of catlean_1.21.11-v0.1.2.jar?
Community
Member reviews and reports for this exact file hash.